Close Menu
globalcrimedesk.comglobalcrimedesk.com
    What's Hot

    ‘We were poor, but at least we were together’: families of Nepali workers killed in Saudi Arabia wait for justice | Saudi Arabia

    Trump says Delhi willing to charge ‘no tariffs’ on US goods

    Climber describes how he narrowly survived 400-foot fall that killed 3 others

    Facebook X (Twitter) Instagram
    Trending
    • ‘We were poor, but at least we were together’: families of Nepali workers killed in Saudi Arabia wait for justice | Saudi Arabia
    • Trump says Delhi willing to charge ‘no tariffs’ on US goods
    • Climber describes how he narrowly survived 400-foot fall that killed 3 others
    • ‘Significant step’: Russia-Ukraine talks in Turkiye – what to expect | Conflict News
    • Russia-Ukraine war: List of key events, day 1,176 | Russia-Ukraine war News
    • ‘Adolescence’ is right: We’re failing both young men and women | Gender Equity
    • Ukraine war live: First direct talks between Moscow and Kyiv in three years set to begin in Turkey | Russia
    • Tory Lanez recovering after prison stabbing attack : NPR
    Facebook X (Twitter) Instagram
    globalcrimedesk.comglobalcrimedesk.com
    • Home
    • Cyber
    • Global
    • Law
    • Mafia
    • Prevention
    • Scandals
    • Terror
    • Trafficking
    globalcrimedesk.comglobalcrimedesk.com
    Home»Cyber»Education giant Pearson hit by cyberattack exposing customer data
    Cyber

    Education giant Pearson hit by cyberattack exposing customer data

    mediamillion1000@gmail.comBy [email protected]May 11, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
    Follow Us
    Google News Flipboard
    Education giant Pearson hit by cyberattack exposing customer data
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    Education giant Pearson hit by cyberattack exposing customer data

    Education giant Pearson suffered a cyberattack, allowing threat actors to steal corporate data and customer information, BleepingComputer has learned.

    Pearson is a UK-based education company and one of the world’s largest providers of academic publishing, digital learning tools, and standardized assessments. The company works with schools, universities, and individuals in over 70 countries through its print and online services.

    In a statement to BleepingComputer, Pearson confirmed they suffered a cyberattack and that data was stolen, but stated it was mostly “legacy data.”

    “We recently discovered that an unauthorized actor gained access to a portion of our systems,” a Pearson representative confirmed to BleepingComputer.

    “Once we identified the activity, we took steps to stop it and investigate what happened and what data was affected with forensics experts. We also supported law enforcement’s investigation. We have taken steps to deploy additional safeguards onto our systems, including enhancing security monitoring and authentication.”

    “We are continuing to investigate, but at this time we believe the actor downloaded largely legacy data. We will be sharing additional information directly with customers and partners as appropriate.”

    Pearson also confirmed that the stolen data did not include employee information.

    Do you have information about this or another cyberattack? If you want to share the information, you can contact us securely and confidentially on Signal at LawrenceA.11, via email at [email protected], or by using our tips form.

    An exposed GitLab token

    This statement comes after sources told BleepingComputer that threat actors compromised Pearson’s developer environment in January 2025 through an exposed GitLab Personal Access Token (PAT) found in a public .git/config file.

    A .git/config file is a local configuration file used by Git projects to store configuration settings, such as a project name, email address, and other information. If this file is mistakenly exposed and contains access tokens embedded in remote URLs, it can give attackers unauthorized access to internal repositories.

    In the attack on Pearson, the exposed token allowed the threat actors to access the company’s source code, which contained further hard-coded credentials and authentication tokens for cloud platforms.

    Over the following months, the threat actor reportedly used these credentials to steal terabytes of data from the company’s internal network and cloud infrastructure, including AWS, Google Cloud, and various cloud-based database services such as Snowflake and Salesforce CRM.

    This stolen data allegedly contains customer information, financials, support tickets, and source code, with millions of people impacted.

    However, when BleepingComputer asked Pearson about whether they paid a ransom, what they meant by “legacy data,” how many customers were impacted, and if customers would be notified, the company responded that they would not be commenting on these questions.

    Pearson previously disclosed in January that they were investigating a breach of one of their subsidiaries, PDRI, which is believed to be related to this attack.

    Scanning for Git configuration files and exposed credentials has become a common method for threat actors to breach cloud services.

    Last year, Internet Archive was breached after threat actors discovered an exposed Git configuration file containing an authentication token for the company’s GitLab repositories.

    For this reason, it is critical to secure “.git/config” files by preventing public access and to avoid embedding credentials in remote URLs.

    Red Report 2025

    Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

    customer cyberattack Data Education exposing giant hit Pearson
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleCare worker recruitment from abroad to end, Home Secretary Yvette Cooper says
    Next Article Trump offers to work with India, Pakistan on Kashmir ‘solution’ | India-Pakistan Tensions News
    [email protected]
    • Website

    Related Posts

    Ransomware gangs join ongoing SAP NetWeaver attacks

    May 15, 2025

    Meet your new colleague – the Machine Learning Admin • The Register

    May 15, 2025

    Die acht wichtigsten Sicherheitsmetriken

    May 15, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Latest Posts

    ‘We were poor, but at least we were together’: families of Nepali workers killed in Saudi Arabia wait for justice | Saudi Arabia

    Trump says Delhi willing to charge ‘no tariffs’ on US goods

    Climber describes how he narrowly survived 400-foot fall that killed 3 others

    ‘Significant step’: Russia-Ukraine talks in Turkiye – what to expect | Conflict News

    Trending Posts

    ‘We were poor, but at least we were together’: families of Nepali workers killed in Saudi Arabia wait for justice | Saudi Arabia

    May 15, 2025

    Trump says Delhi willing to charge ‘no tariffs’ on US goods

    May 15, 2025

    Climber describes how he narrowly survived 400-foot fall that killed 3 others

    May 15, 2025

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    News

    • Cyber
    • Global
    • Law
    • Mafia
    • Prevention

    Company

    • About Us
    • Disclaimer
    • Get In Touch
    • Privacy policy
    • Terms & Condition
    Recent Posts
    • ‘We were poor, but at least we were together’: families of Nepali workers killed in Saudi Arabia wait for justice | Saudi Arabia
    • Trump says Delhi willing to charge ‘no tariffs’ on US goods

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2025 globalcrimedesk. Designed by Pro.
    Facebook X (Twitter) Pinterest Vimeo WhatsApp TikTok Instagram

    Type above and press Enter to search. Press Esc to cancel.